CVE-2025-50199: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50199 is a blind Server-Side Request Forgery (SSRF) vulnerability in Chamilo LMS, a widely used open-source learning management system. The flaw exists in /index.php and is exploitable via the POST openid_url parameter, allowing unauthenticated attackers to make arbitrary server-side HTTP requests. It affects all Chamilo LMS versions up to and including 1.11.28, and was patched in version 1.11.30, released as a security patch release. The vulnerability was disclosed on March 2, 2026, and was discovered by Aleksey Solovev of Positive Technologies. It carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 score of 7.7 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is insufficient validation of the destination address before the application sends an HTTP request, classified as CWE-918 (Server-Side Request Forgery). The vulnerable component is /index.php, where the openid_url POST parameter is processed without adequate sanitization or allowlist enforcement, enabling the server to be directed to make requests to arbitrary internal or external hosts. Exploitation requires the OpenID module to be enabled, which is disabled by default, but any unauthenticated external user can exploit it when the module is active. Because the SSRF is "blind," attackers cannot directly read responses but can infer system behavior through timing analysis and error differentiation, enabling internal network mapping and port scanning (GitHub Advisory).

Impact

Successful exploitation allows unauthenticated attackers to probe internal network segments inaccessible from the internet, interact with backend services (e.g., databases, cloud metadata endpoints), and potentially exfiltrate sensitive information through timing-based inference. The blind nature of the SSRF limits direct data readability but still enables discovery of internal infrastructure, port/service enumeration, and potential abuse of internal APIs or services. In cloud-hosted environments, attackers may be able to reach instance metadata services (e.g., AWS IMDSv1), potentially leading to credential theft and lateral movement (GitHub Advisory, Red Hat CVE).

Exploitability

A proof-of-concept reference is publicly available via the GitHub Security Advisory, though no weaponized exploit kit or active in-the-wild exploitation has been confirmed as of the disclosure date. The EPSS score is approximately 0.041%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the OpenID module to be enabled (disabled by default), which reduces the effective attack surface (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Chamilo LMS instances running versions ≤1.11.28 using search engines like Shodan or Censys, filtering for Chamilo login pages.
  2. Check OpenID module status: Attempt to access the OpenID login flow via /index.php to determine if the OpenID module is enabled (a prerequisite for exploitation).
  3. Craft malicious POST request: Send an HTTP POST request to /index.php with the openid_url parameter set to a target internal address (e.g., http://169.254.169.254/latest/meta-data/ for AWS metadata, or http://192.168.1.1/ for internal hosts).
  4. Infer responses via timing/errors: Since the SSRF is blind, analyze response timing differences and HTTP error codes to determine whether the target host/port is reachable, enabling internal network mapping and port scanning.
  5. Enumerate internal services: Iterate over common internal IP ranges and ports to map the internal network topology and identify accessible backend services.
  6. Leverage discovered services: Use knowledge of internal services (e.g., unauthenticated admin panels, cloud metadata APIs) to escalate access or exfiltrate credentials (GitHub Advisory).

Indicators of compromise

  • Network: Unusual outbound HTTP/HTTPS connections from the Chamilo web server to internal RFC1918 addresses (e.g., 10.x.x.x, 172.16.x.x, 192.168.x.x) or cloud metadata endpoints (169.254.169.254); outbound connections to unexpected external hosts originating from the web server process.
  • Logs: Web server access logs showing repeated POST requests to /index.php with openid_url values containing internal IP addresses, localhost references, or non-standard URL schemes (e.g., file://, ftp://, dict://); high volumes of requests with varying openid_url values suggesting automated scanning.
  • Application Logs: Chamilo application logs showing OpenID authentication attempts with malformed or suspicious URLs in the openid_url field.
  • Process: Unusual network connections initiated by the PHP-FPM or Apache/Nginx worker processes to internal network segments not normally accessed by the web application (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which was released as a dedicated security patch release (Chamilo Release). Organizations unable to patch immediately should disable the OpenID module if it is not required, as the vulnerability is only exploitable when this module is enabled. Additional mitigations include implementing network egress controls to restrict the Chamilo server's outbound connections to only necessary hosts and ports, enforcing strict input validation on the openid_url parameter (allowlist of permitted domains/IPs), disabling HTTP redirects on the server, and restricting URL schemes to HTTP/HTTPS only. Monitoring POST requests to /index.php for suspicious openid_url values is also recommended (GitHub Advisory).

Community reactions

The vulnerability was discovered by Aleksey Solovev of Positive Technologies and disclosed via the Chamilo GitHub Security Advisory on March 2, 2026. Red Hat has tracked the CVE in their security advisory database. No significant broader media coverage or notable community debate has been identified beyond standard vulnerability database aggregation (GitHub Advisory, Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management